CVE-2010-2743: High severity Microsoft Windows 2003 Server vulnerability
The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running the listed Microsoft Windows products are affected, including Windows XP, Windows Vista, Windows 7, Windows Server 2003, and Windows Server 2008. Exploitation requires local access rather than network access.
What does an attacker need to exploit it?
An attacker needs to run a crafted application locally. No authentication is required according to the supplied vector, and successful exploitation can result in elevated privileges with confidentiality, integrity, and availability impact.
Has this issue been used in real-world attacks?
Yes. The description states that the issue was demonstrated in the wild in July 2010 by the Stuxnet worm.
How can I identify relevant systems?
Identify endpoints and servers running the listed Windows versions, then consult the referenced OVAL definition and Microsoft security bulletin MS10-073 to assess their update status.